LiveActive security incident?Get immediate response
CVE Record

CVE-2023-52705: nilfs2: fix underflow in second superblock position calculations

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second superblock, underflows when the argument device size is less than 4096 bytes. Therefore, when using this macro, it is necessary to check in advance that the device size is not less than a lower limit, or at least that underflow does not occur. The current nilfs2 implementation lacks this check, causing out-of-bound block access when mounting devices smaller than 4096 bytes: I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0 phys_seg 1 prio class 2 NILFS (loop0): unable to read secondary superblock (blocksize = 1024) In addition, when trying to resize the filesystem to a size below 4096 bytes, this underflow occurs in nilfs_resize_fs(), passing a huge number of segments to nilfs_sufile_resize(), corrupting parameters such as the number of segments in superblocks. This causes excessive loop iterations in nilfs_sufile_resize() during a subsequent resize ioctl, causing semaphore ns_segctor_sem to block for a long time and hang the writer thread: INFO: task segctord:5067 blocked for more than 143 seconds. Not tainted 6.2.0-rc8-syzkaller-00015-gf6feea56f66d #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:segctord state:D stack:23456 pid:5067 ppid:2 flags:0x00004000 Call Trace: <TASK> context_switch kernel/sched/core.c:5293 [inline] __schedule+0x1409/0x43f0 kernel/sched/core.c:6606 schedule+0xc3/0x190 kernel/sched/core.c:6682 rwsem_down_write_slowpath+0xfcf/0x14a0 kernel/locking/rwsem.c:1190 nilfs_transaction_lock+0x25c/0x4f0 fs/nilfs2/segment.c:357 nilfs_segctor_thread_construct fs/nilfs2/segment.c:2486 [inline] nilfs_segctor_thread+0x52f/0x1140 fs/nilfs2/segment.c:2570 kthread+0x270/0x300 kernel/kthread.c:376 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:308 </TASK> ... Call Trace: <TASK> folio_mark_accessed+0x51c/0xf00 mm/swap.c:515 __nilfs_get_page_block fs/nilfs2/page.c:42 [inline] nilfs_grab_buffer+0x3d3/0x540 fs/nilfs2/page.c:61 nilfs_mdt_submit_block+0xd7/0x8f0 fs/nilfs2/mdt.c:121 nilfs_mdt_read_block+0xeb/0x430 fs/nilfs2/mdt.c:176 nilfs_mdt_get_block+0x12d/0xbb0 fs/nilfs2/mdt.c:251 nilfs_sufile_get_segment_usage_block fs/nilfs2/sufile.c:92 [inline] nilfs_sufile_truncate_range fs/nilfs2/sufile.c:679 [inline] nilfs_sufile_resize+0x7a3/0x12b0 fs/nilfs2/sufile.c:777 nilfs_resize_fs+0x20c/0xed0 fs/nilfs2/super.c:422 nilfs_ioctl_resize fs/nilfs2/ioctl.c:1033 [inline] nilfs_ioctl+0x137c/0x2440 fs/nilfs2/ioctl.c:1301 ... This fixes these issues by inserting appropriate minimum device size checks or anti-underflow checks, depending on where the macro is used.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2023-52705 is a Linux kernel NILFS2 filesystem bug. Very small block devices can make a size calculation wrap around, leading to out-of-bounds reads during mount or long blocking/hang behavior during resize. The documented impact is availability and reliability, not data theft or remote compromise.

Executive priority

Treat as a routine-to-priority kernel maintenance item for environments using NILFS2 or handling untrusted filesystem images. It is not documented as actively exploited, but it can affect system availability and should be patched through normal kernel update channels.

Technical view

The NILFS_SB2_OFFSET_BYTES macro can underflow when device size is below 4096 bytes. Missing checks in NILFS2 mount and resize paths can cause out-of-bound block access or corrupt resize parameters, leading to excessive nilfs_sufile_resize() iterations and blocked segctord writer activity.

Likely exposure

Exposure is limited to Linux systems with NILFS2 support where small, malformed, or untrusted block devices/filesystem images may be mounted or resized. General servers not using NILFS2 have lower practical exposure, but distribution kernels may still include the code.

Exploitation context

The source bundle does not show CISA KEV listing, active exploitation, public exploit use, or remote attack evidence. The documented trigger involves mounting devices smaller than 4096 bytes or resizing a NILFS2 filesystem below that size.

Researcher notes

The vulnerability centers on an integer underflow in second-superblock offset calculation for sub-4096-byte devices. The fix adds minimum-size or anti-underflow checks where the macro is used. Evidence supports denial-of-service style outcomes; confidentiality and integrity impact are not established in the bundle.

Mitigation direction

  • Apply Linux kernel or distribution updates containing the referenced stable NILFS2 fixes.
  • Check vendor advisories for the exact fixed kernel package for your platform.
  • Avoid mounting or resizing untrusted NILFS2 images until patched.
  • Limit NILFS2 filesystem operations to trusted administrators and trusted media.

Validation and detection

  • Inventory systems running kernels in the affected version range.
  • Check whether NILFS2 support is present or loaded on those systems.
  • Confirm installed kernel includes the relevant stable fix commit or vendor backport.
  • Review logs for NILFS mount I/O errors or hung segctord messages.
Prepared
Confidence
high
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-52705 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxe339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7, e339ad31f59925b48a92ee3947692fdf9758b8c7unaffected
LinuxLinux2.6.30, 0, 4.14.306, 4.19.273, 5.4.232, 5.10.169, 5.15.95, 6.1.13, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.